What ShipIsland stores
Provider credentials and private-key material are stored in macOS Keychain. Normalized events, connection metadata, selected resources, synchronization cursors, notification history, and issue-action audit records are stored in the app’s local database.
Connection records contain a non-secret Keychain lookup reference, never the credential itself. Optional AI output lasts only for the current app session.
Direct provider connections
ShipIsland contacts a provider’s official API directly from your Mac only after you configure that connection. ShipIsland does not proxy, sell, or receive those requests or the returned provider data.
Your use of GitHub, Vercel, RevenueCat, App Store Connect, and other connected services remains subject to each provider’s own terms and privacy policy.
Optional AI requests
OpenAI and Anthropic integrations are disabled by default. If you configure your own provider account and explicitly choose Generate, ShipIsland sends the displayed investigation context directly to that provider. The AI provider’s account, billing, retention, and data-control policies apply.
Permissions
- Outgoing network access for configured provider APIs.
- Keychain access to save and remove provider credentials.
- Optional notifications for local alerts, requested in context.
- Optional Login Items access when you enable Launch at Login.
- User-selected file access when choosing an App Store Connect .p8 key or exporting diagnostics.
Diagnostics
A diagnostics export happens only when you request it and choose a save location. It contains app and system versions, aggregate counts, connection health, retry categories, sanitized errors, and action outcomes. It excludes credentials, Keychain values, provider payloads, event titles and summaries, URLs, resource identifiers, and notification content. Review any diagnostics file before sharing it.
Your controls and deletion
Disconnecting a provider deletes its Keychain credential before removing the local connection record. You can disable notifications, Launch at Login, Lock Screen visibility, and optional AI at any time in Settings.
Before uninstalling, disconnect providers to remove their Keychain items. macOS may retain an app sandbox container or Keychain entry after the app itself is deleted.
Updates and changes
Mac App Store builds receive updates through Apple. A signed direct-download build may check ShipIsland’s HTTPS update feed; the feed contains release metadata and executable code, not provider credentials or local events.
Material changes to this policy will be published on this page with a revised date.
Contact
Privacy questions can be sent to [email protected].